77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
News & Insights

What officers need to know.

Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Latest
AGG Complaints Office 2026: Pricing, Models & Costs
Equality & AGG10 August 202610 min read

AGG Complaints Office 2026: Pricing, Models & Costs

What does an AGG complaints office cost in 2026? Compare internal expenses, standalone software pricing, and external service provider models.

Read more
AGG Complaints Office: Internal or External Compared
Equality & AGG10 August 202611 min read

AGG Complaints Office: Internal or External Compared

A complaints office under § 13 AGG is mandatory for every employer. Compare internal and external solutions regarding costs, effort, and liability risks.

Read more
Dangerous goods officer exam questions 2021: What has changed and what is important today
Dangerous Goods & Logistics10 August 202612 min read

Dangerous goods officer exam questions 2021: What has changed and what is important today

Anyone looking for IHK exam questions for the dangerous goods officer in 2021 came across a catalogue that was stable at the time. With the 2023 ADR amendment and the 2025 update, the examination material has shifted. This article classifies the change and shows what a modern order has to achieve today.

Read more
ADR 1.1.4.2.1 explains: transport document, multimodality and pre-transport
Dangerous Goods & Logistics10 August 202614 min read

ADR 1.1.4.2.1 explains: transport document, multimodality and pre-transport

Section 1.1.4.2.1 ADR regulates the transfer of transport that does not take place exclusively by road. Anyone who prepares containers for the port or drives a truck to the shipping company must know the requirements, otherwise the freight forwarder will block them.

Read more
ADR certificate online: What works digitally, what doesn't and who is liable
Dangerous Goods & Logistics10 August 202613 min read

ADR certificate online: What works digitally, what doesn't and who is liable

The ADR certificate cannot be purchased entirely online. This article clarifies which parts of the training are permitted digitally, which IHK examination requires attendance and how you as a company can organise the evidence in an audit-proof manner.

Read more
Dangerous goods 30/1863: Transport and document jet fuel in accordance with ADR
Dangerous Goods & Logistics10 August 202612 min read

Dangerous goods 30/1863: Transport and document jet fuel in accordance with ADR

Dangerous goods 30/1863 identifies jet fuel as a flammable liquid substance of ADR class 3. We explain the obligations according to ADR 2025, GbV and the CIVAC model for the dangerous goods officer as a service.

Read more
Dangerous goods ADR: duties, classes and representatives at a glance
Dangerous Goods & Logistics10 August 202612 min read

Dangerous goods ADR: duties, classes and representatives at a glance

Anyone who ships, transports or loads dangerous goods by road falls under the ADR and the GbV. This article explains classes, exemptions, duties and appointment of the dangerous goods officer, with specific thresholds and audit examples from 2026.

Read more
30/1202 Dangerous goods: What the Kemler number means for diesel fuel
Dangerous Goods & Logistics9 August 202612 min read

30/1202 Dangerous goods: What the Kemler number means for diesel fuel

The orange warning sign with 30/1202 marks the transport of diesel fuel, gas oil or heating oil, slightly according to ADR. This guide explains the Kemler number, UN number, labelling requirements and the role of the dangerous goods officer.

Read more
BSI C5: What the criteria catalogue for cloud compliance requires
IT Security & NIS-29 August 202613 min read

BSI C5: What the criteria catalogue for cloud compliance requires

The BSI C5 is the German de facto standard for cloud compliance. This article describes the structure, criteria structure, the relationship to ISO/IEC 27001:2022 and how CIVAC halves the mapping effort between ISMS, C5 and client requirements.

Read more
Risk analysis with ISO 27001 Annex A: Template, Method and SoA
IT Security & NIS-29 August 202613 min read

Risk analysis with ISO 27001 Annex A: Template, Method and SoA

Risk analysis is the heart of every ISMS according to ISO/IEC 27001:2022. This guide shows what a reliable template looks like, how the 93 controls from Appendix A are integrated and how the Statement of Applicability (SoA) is created.

Read more
NIS-2 Implementation Germany: How to Operate the 2026 Deadline as an Officer, Not a Project
IT-Sicherheit & NIS-29 August 202612 min read

NIS-2 Implementation Germany: How to Operate the 2026 Deadline as an Officer, Not a Project

The 2026 implementation phase of NIS-2 in Germany shifts the burden from legal interpretation to operational execution. This guide focuses on the officer angle: how to staff, structure, and report a NIS-2 program under Section 38 BSIG without burning out the team.

Read more
DORA Regulation: A Practical Guide to the Digital Operational Resilience Act for Financial Entities
IT Security & NIS-29 August 202613 min read

DORA Regulation: A Practical Guide to the Digital Operational Resilience Act for Financial Entities

Regulation (EU) 2022/2554 (DORA) became applicable on 17 January 2025, binding banks, insurers, investment firms, and critical ICT third parties to five pillars of digital operational resilience. We translate the legal text into operational checklists.

Read more
Virtual CISO Services for SaaS Companies in Germany: The Pragmatic Playbook
IT Security & NIS-29 August 202612 min read

Virtual CISO Services for SaaS Companies in Germany: The Pragmatic Playbook

A pragmatic playbook for SaaS leaders in Germany who need NIS-2 coverage, ISO 27001 readiness and credible answers to enterprise security questionnaires, without hiring a six-figure CISO. Scope, deliverables, pricing and the dual delivery model explained.

Read more
External CISO vs. internal CISO: cost comparison, risks and selection criteria
IT Security & NIS-28 August 202613 min read

External CISO vs. internal CISO: cost comparison, risks and selection criteria

An internal CISO costs 180,000 to 280,000 euros per year including additional costs. External CISO-as-a-Service models range from 36,000 to 180,000 euros, depending on depth. This comparison shows when which variant is worthwhile.

Read more
TISAX certification 2026: Scope, test levels and effort realistically planned
IT Security & NIS-28 August 202613 min read

TISAX certification 2026: Scope, test levels and effort realistically planned

TISAX is the German automotive industry’s de-facto requirement for information security in the supply chain. This article explains the scope, assessment levels, test procedure and the clean integration with ISO/IEC 27001:2022.

Read more
ISO 27001 certification: process in eight steps from gap analysis to re-audit
IT Security & NIS-28 August 202613 min read

ISO 27001 certification: process in eight steps from gap analysis to re-audit

The path to ISO 27001:2022 certification can be divided into eight clearly defined steps. We show what is required in the gap analysis, scope, risk assessment, statement of applicability, stage 1 and stage 2 audit and what deadlines you should plan for.

Read more
ESG at Heineken: What breweries can learn from the 2026 sustainability report for their own CSRD obligations
ESG & Sustainability8 August 202614 min read

ESG at Heineken: What breweries can learn from the 2026 sustainability report for their own CSRD obligations

Heineken is one of the first European companies to completely prepare their sustainability reporting according to CSRD and ESRS. This article analyses the structure, priorities and lessons learned for medium-sized breweries and beverage manufacturers in the DACH region.

Read more
Amundi Global Ecology ESG: Classification and obligations for companies related to ESG
ESG & Sustainability8 August 202612 min read

Amundi Global Ecology ESG: Classification and obligations for companies related to ESG

Amundi Global Ecology ESG is an Article 8 SFDR rated equity fund with an ecological focus. This guide classifies the product from a regulatory perspective and shows what obligations ESG-related companies have to make investment decisions and reporting.

Read more
Sustainable finance at German banks: SFDR, CSRD and EU taxonomy in interaction
ESG & Sustainability7 August 202614 min read

Sustainable finance at German banks: SFDR, CSRD and EU taxonomy in interaction

German banks are increasingly demanding reliable ESG data from corporate customers along with their SFDR, CSRD and taxonomy obligations. Anyone who does not systematically collect the required key figures risks a deterioration in financing and conditions. A classification for treasury, ESG and management.

Read more
MSCI EMU Climate Change ESG: what the index means for ESG officers
ESG & Sustainability7 August 202613 min read

MSCI EMU Climate Change ESG: what the index means for ESG officers

The MSCI EMU Climate Change Index is more than an investment product. It shapes which companies institutional investors with a climate focus still own. Anyone responsible for ESG should understand how the index logic affects their own cost of capital side.

Read more
MSCI World ESG or SRI: Differences and implications for corporate compliance
ESG & Sustainability7 August 202613 min read

MSCI World ESG or SRI: Differences and implications for corporate compliance

MSCI World ESG and MSCI World SRI are both sustainable index variants, but with significantly different filter strictness. Anyone who knows the methodology understands the expectations of institutional investors and can align their own ESG reporting accordingly.

Read more
Deka Future Energy ESG: What companies learn from the fund for their compliance
ESG & Sustainability7 August 202613 min read

Deka Future Energy ESG: What companies learn from the fund for their compliance

The Deka Future Energy ESG illustrates which ESG criteria capital market players are examining today. We show what companies learn from the fund logic according to SFDR, EU taxonomy and ESRS and how the compliance platform CIVAC turns them into verifiable reports.

Read more
DWS, ESG and the lessons for German companies with ESG obligations
ESG & Sustainability7 August 202614 min read

DWS, ESG and the lessons for German companies with ESG obligations

The DWS case has put ESG compliance on the board agenda: greenwashing allegations, regulatory investigations, reputational damage. Anyone who is responsible for ESG today needs risk analysis, documented controls, a reporting line to management and an ESG officer with a clear mandate.

Read more
ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026
IT-Sicherheit & NIS-27 August 202613 min read

ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026

Choosing an ISO 27001 implementation consultant in Berlin: scope, deliverables, timelines, costs, and the difference between a consultant who runs the project and one who hands you a templated PDF.

Read more